ISO 9001

ISO 9001 and the Legal Register: What You Need to Know

What is ISO 9001?

ISO 9001 is the world’s most widely used standard for Quality Management Systems (QMS). It sets out a framework of requirements that help organisations consistently deliver products and services that meet customer and regulatory expectations, while driving continual improvement. Certification demonstrates to customers, regulators and stakeholders that your business has robust, auditable processes in place.

ISO 9001 legal register

ISO 9001 requires you to know your legal obligations.

Where legal compliance fits into ISO 9001

Legal and regulatory compliance runs through several parts of the standard:

  • Clause 4.1 requires you to understand the external issues relevant to your organisation’s context — including legal and regulatory factors.
  • Clause 4.2 requires you to identify the relevant requirements of interested parties, which frequently includes statutory and regulatory bodies.
  • Clause 8.2.2 requires you to determine the statutory and regulatory requirements applicable to your products and services before you commit to supplying them.

In practice, most organisations meet these requirements — and provide clear audit evidence — by maintaining a register of legal and other requirements (often called a “legal register”). This is also the explicit, named requirement under ISO 14001 (clause 6.1.3) and ISO 45001 (clause 6.1.3), so if you hold or are pursuing certification to those standards too, a legal register becomes essential rather than optional.

What is a legal register?

A legal register is a living document that lists every piece of legislation, regulation, code of practice, and other requirement relevant to your organisation’s operations. For each entry, it typically records:

  • The legislation or requirement and what it covers
  • How it applies to your specific operations
  • The actions or controls needed to demonstrate compliance
  • Who is responsible for maintaining that compliance
  • Review dates, to keep pace with legislative change

Done well, a legal register isn’t just a compliance checkbox — it’s a practical risk-management tool that gives management real visibility of legal exposure.

Why a bespoke legal register beats a generic template

Off-the-shelf legal registers are built for “an organisation like yours” — not specifically yours. They often include irrelevant legislation, miss sector-specific requirements, and quickly go out of date. A bespoke register is built around:

  • Your actual sites, activities, and industry sector
  • The jurisdictions you operate in (e.g. GB, Northern Ireland, Isle of Man, Republic of Ireland)
  • Your existing management systems, so it integrates cleanly with your QMS, EMS or OH&S system
  • A structure your auditors will recognise and accept without query

How Ashbrooke can help

We build and maintain bespoke legal registers that satisfy the requirements of ISO 9001, ISO 14001 and ISO 45001. Our service includes:

  • A full review of your operations to identify every applicable legal requirement
  • A clearly structured, audit-ready register mapped to the relevant standard’s clauses
  • Ongoing legislative monitoring, so your register stays current as laws change
  • Practical guidance on closing any compliance gaps we identify
  • Support during external audits and certification reviews

Whether you’re preparing for first-time certification or need to bring an existing register up to standard, we’ll build you a legal register that stands up to scrutiny — and actually helps you manage risk day to day.

Get in touch to discuss a bespoke legal register for your business